[cli][menu-bar] Add iOS re-signing with a free Apple ID - #372
Draft
gabrieldonadel wants to merge 2 commits into
Draft
gabrieldonadel wants to merge 2 commits into
gabrieldonadel wants to merge 2 commits into
Conversation
Re-sign an installed build that fails code-signing so it runs on a personal device, using a free Apple ID. When an install fails with APPLE_APP_VERIFICATION_FAILED, Orbit offers to re-sign and install. - CLI: `resign-ipa` and `apple-id-auth` (sign-in / verify-2fa with SMS fallback / sign-out) commands, driven by ipa-resign. - Menu-bar: the resign offer + determinate progress in the popover, an Apple ID sign-in window (6-digit 2FA input, resend, SMS fallback), error-copy mapping, first-install "Untrusted Developer" trust instructions, and an Apple ID section in Settings (signed-in state + sign out). - Session expiry is treated as an automatic logout: the stored Apple ID is forgotten and every "signed in as" surface updates, with one-tap re-auth. - Electron/macOS wiring for the ipa-resign native anisette + zsign helpers, transient-env-var plumbing to pass the password to the CLI, and the APPLE_APP_VERIFICATION_FAILED mapping that triggers the offer. ipa-resign@0.0.9.
…less return - forge.config: create ./bin and ./anisette in the generateAssets hook so packaging (and Electron E2E, which runs 'yarn package' without 'build:helpers') does not fail with ENOENT on the missing extraResource dirs. build:helpers still populates them for real builds. - build-helpers: remove a no-useless-return that failed eslint --max-warnings 0.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
EAS internal-distribution and development builds are code-signed for a fixed set of provisioned devices. If your iPhone is not on that build's provisioning profile, installing it fails verification and there is no way to run it locally without re-provisioning on EAS or rebuilding through Xcode. That round trip is slow and, for a build someone else produced, often not possible at all.
This lets you re-sign such a build with a free Apple ID so it installs and runs on your personal device, in one click, straight from Orbit. Free is the point: no paid Apple Developer Program membership is required.
This is the base of a two-PR stack. It adds the manual re-sign flow only; automatic 7-day renewal and App ID quota management are in the stacked follow-up PR.
How
When an install fails with a code-signature verification error, Orbit offers to re-sign and install instead of dead-ending. The heavy lifting (Apple ID auth via GSA/SRP + anisette, minting a certificate and provisioning profile on your free personal team, and codesigning) lives in the
ipa-resignpackage; Orbit drives it through the bundled CLI and owns the UX around it.Design decisions worth reviewing:
ipa-resign's own store under~/.orbit, not in Orbit. The Settings copy states this plainly.ipa-resign's WASM anisette emulator, so no per-platform native anisette build is needed.Test Plan
Automated (run in
apps/cliandapps/menu-bar): typecheck, lint, and unit tests pass; the packaged CLI builds for botharm64andx64and returns clean JSON fromlist-app-ids/apple-id-authprobes; a dummy-credential sign-in exercises the full SRP/GSA path to Apple and comes back with a real "incorrect account information" response (proving auth + crypto work end to end in the pkg binary).Manual (needs a physical iPhone and an internal-distribution build not provisioned for it):
~/.orbit/apple-resign/secrets.jsonand re-sign: Orbit should treat it as a logout and re-prompt with the email pre-filled rather than erroring.